You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CVE-2022-32207漏洞求助:升级Jib与基础镜像仍未解决问题

问题:Spring+Gradle项目Trivy扫描出curl高危漏洞无法解决

背景

我维护一个基于Spring和Gradle的Java项目,每次提交新代码后,流水线会通过Trivy执行安全扫描步骤,近期扫描发现以下高危漏洞:

2022-11-09T08:43:14.846Z    INFO    Vulnerability scanning is enabled
2022-11-09T08:43:14.846Z    INFO    Secret scanning is enabled
2022-11-09T08:43:14.846Z    INFO    If your scanning is slow, please try '--security-checks vuln' to disable secret scanning
2022-11-09T08:43:15.018Z    INFO    Detected OS: amazon
2022-11-09T08:43:15.018Z    INFO    Detecting Amazon Linux vulnerabilities...
2022-11-09T08:43:15.022Z    INFO    Number of language-specific files: 1
2022-11-09T08:43:15.022Z    INFO    Detecting jar vulnerabilities...
(amazon 2 (Karoo))
===========================================================================
Total: 2 (CRITICAL: 2)
┌─────────┬────────────────┬──────────┬────────────────────┬────────────────────┬────────────────────────────────────────────┐
│ Library │ Vulnerability  │ Severity │ Installed Version  │   Fixed Version    │                   Title                    │
├─────────┼────────────────┼──────────┼────────────────────┼────────────────────┼────────────────────────────────────────────┤
│ curl    │ CVE-2022-32207 │ CRITICAL │ 7.79.1-4.amzn2.0.1 │ 7.79.1-6.amzn2.0.1 │ curl: Unpreserved file permissions         │
│         │                │          │                    │                    │ https://avd.aquasec.com/nvd/cve-2022-32207 │
├─────────┤                │          │                    │                    │                                            │
│ libcurl │                │          │                    │                    │                                            │
│         │                │          │                    │                    │                                            │
└─────────┴────────────────┴──────────┴────────────────────┴────────────────────┴────────────────────────────────────────────┘

我排查了后端代码,未发现任何与curl相关的内容,经多方排查及同事建议,推测漏洞来自Gradle配置中的Jib任务,原配置如下:

plugins {
    id 'com.google.cloud.tools.jib' version '3.1.2'
}

// some other dependencies... 

jib {
    from {
        image = 'amazoncorretto:18'
        platforms {
            platform {
                architecture = 'amd64'
                os = 'linux'
            }
        }
    }
    to {
        image = System.env.CI_REGISTRY + '/myproject'
        tags = [System.env.CI_COMMIT_SHORT_SHA, 'latest']
        auth {
            username = System.env.CI_REGISTRY_USER ?: ''
            password = System.env.CI_REGISTRY_PASSWORD ?: ''
        }

    }
}

我尝试了两种解决方法,但漏洞问题仍未解决:

  • 将Jib版本升级至3.2.0
    plugins {
        id 'com.google.cloud.tools.jib' version '3.2.0'
    }
    
  • 更换基础镜像为amazoncorretto:19

请问还有什么其他解决办法?感谢解答。

内容的提问来源于stack exchange,提问作者ale.soft

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.13 01:25:39